Thursday, February 14, 2019

Watchguard firewall is unable to reach a domain controller over a branch office VPN to AWS - but all other devices can.

Hi,

I'm setting up a backup domain controller on AWS and a VPN between the office and the VPC. Everything went fine: promoted the server and all went good... Until I tried to add the new domain controller in the Watchguard authentication servers configuration. Somehow, the firewall can't reach the DC!

I can ping the firewall from the DC, but I can't ping the DC from the firewall itself. So the device routes everything correctly, but its internal services cannot access the server.

I use the default BOVPN rules and everything should be able to reach the other side of the tunnel, even the firewall itself! I modified my ping rule to be able to see them in the logs, but I'm not seeing any from the firewall when I run my test.

So far, I'm satisfied of our Watchguard firewalls, but this issue is really weird... I'm running the latest version of the Firebox software.

If someone has any idea, don't hesitate. I opened a customer support case for this issue and will report back if they're able to give me a solution.



No comments:

Post a Comment